Andrew Mercer
on this page

What it is

nping ships with nmap and does what ping can't: craft raw TCP, UDP, ICMP, and ARP packets with custom flags, payloads, and timing, then report on responses. Where ping only speaks ICMP echo, nping lets you test actual TCP reachability (does anyone answer on port 443, ICMP aside), or ARP-probe a local network without an IP handshake at all.

Installation

sudo apt-get install nmap    # nping is bundled with the nmap package

TCP ping (bypass ICMP filtering)

sudo nping --tcp -p 443 -c 3 example.com

Many hosts and firewalls drop ICMP but still answer TCP SYN — this is the most common reason ping reports 100% loss while the service is actually fine. --tcp with a SYN to an open port gets a SYN/ACK back even with ICMP fully blocked.

UDP probing

sudo nping --udp -p 53 -c 3 8.8.8.8

UDP is connectionless, so "success" here just means the packet was sent and (if the target replies with anything, including an ICMP port-unreachable) you'll see it — it doesn't confirm application-level health the way a TCP handshake does.

ICMP with custom options

sudo nping --icmp -c 3 example.com                        # plain ICMP echo, nping-flavored
sudo nping --icmp --icmp-type 13 -c 1 host                 # ICMP timestamp request (type 13)

ARP probing (local network only)

sudo nping --arp -c 1 192.168.1.1

ARP works below IP, so this confirms a host exists on the local L2 segment even if it's got every IP-layer protocol firewalled off. Useful for confirming "is anything actually plugged in at this address" on a LAN.

Custom TCP flags

sudo nping --tcp -p 80 --flags syn -c 3 host              # SYN only, like a stealth scan probe
sudo nping --tcp -p 80 --flags rst -c 3 host               # RST — see how the target's firewall reacts

Setting a custom payload / TTL

sudo nping --tcp -p 80 --data-string "GET / HTTP/1.0\r\n\r\n" -c 1 host
sudo nping --icmp --ttl 1 -c 1 host                         # forces a "TTL exceeded" from the first hop — manual traceroute step

Cheat sheet

sudo nping --tcp -p 443 -c 3 host           # TCP ping (bypasses ICMP filtering)
sudo nping --udp -p 53 -c 3 host            # UDP probe
sudo nping --icmp -c 3 host                 # ICMP, nping style
sudo nping --arp -c 1 192.168.1.1           # local L2 probe
sudo nping --tcp -p 80 --flags syn -c 3 host   # raw SYN probe